Full control over where your data goes.
Stop routing company data through the United States.
Harriet gives you complete data residency by keeping all processing and storage strictly within Europe.
Enterprise security by design
- EU hosting
- Claude runs in AWS Bedrock in Ireland through the gateway, on the Business tier or higher with managed credits, priced above US list.
- UK hosting
- Available as deployed for the customer.
- One gateway
- Every prompt, connector and tool call goes through one audited path.
- Reviewed before it runs
- Every connector and skill is scanned before approval, and a critical finding blocks it until an owner overrides with a reason on the record.
- Isolated execution
- Hosted connectors and agent workspaces run in sandboxes off the laptop, and upstream tokens never leave Harriet’s servers.
- Never trained on
- LLM providers are contractually barred from training on your data.
- One policy, every model
- Any model, from GPT, Gemini and Claude to open-source models, behind one gateway, with the region and models each team may use decided by you.
- Retention
- Provider retention follows that provider’s terms, and tool-call payload capture is off by default.
- Encryption
- In transit over TLS, and at rest where applicable.
Model usage and BYOK
- Your keys or ours
- Bring your own keys for OpenAI, Anthropic and Google, or use Harriet managed credits, with the same per-team visibility either way.
- Unified API
- Claude, GPT, Gemini and open models behind a single endpoint, with the same policy and audit on every call.
Governance and admin controls
- Identity
- Okta OIDC with SCIM 2.0 provisioning, SSO-only mode, and two-step sign-in the organization can mandate.
- Sign-in options
- Slack, Microsoft and Google sign-in, magic links, and TOTP two-step the organization can mandate.
- Profiles
- Profiles decide which apps, skills and models each job can use, with a per-device model allowlist enforced on Harriet Desktop.
- Tools
- Enable per tool, restrict by role and group, and require human confirmation before a tool runs.
- Bulk syncs
- New tools default to disabled when a sync finds 50 or more.
- Sub-processors
- A live list, with 30 days’ notice before any change. See the list
Audit
- Log
- An append-only, exportable record of person, device, skill, connector, tool, outcome and upstream status.
- Search
- Filter by skill, user, date and traffic type, with every row deep-linkable.
- Retention
- Configurable, with a minimum of seven days.
Legal documents
JustParent Ltd, company number 14338607, London.
What compliance asks first.
Is our data used to train AI models?
No. Customer data is never used to train a Harriet model, and every LLM provider Harriet uses is contractually barred from training on it.
Where is our data processed?
Model calls can be pinned to the EU per team, and the live sub-processor list shows where each provider runs and under which transfer mechanism.
Can we bring our own API keys?
Yes. Bring your own keys for OpenAI, Anthropic and Google and keep your provider contracts, or use Harriet managed credits. Both give the same per-team visibility.
What happens before a connector or skill can run?
It is scanned and banded on submission. A critical finding blocks approval until an owner overrides it, with a reason on the record.
Which certifications does Harriet hold?
SOC 2 Type II, with the current report on the Trust Center, and a GDPR Data Processing Addendum with EU and UK transfer safeguards.
How do we control who can use what?
Profiles decide which apps, skills and models each job can use, and Okta OIDC with SCIM provisioning keeps that in step with your directory.
What happens to our data if we leave?
Customer data is deleted by default within 30 days of contract termination, unless the law requires otherwise.
Book a demo of Harriet.
Bring your security review. We will walk through it with the files your reviewer asks for.